CVE-2018-16541: Use After Free
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect free logic in pagedevice replacement to crash the interpreter.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-16541?
CVE-2018-16541 is a vulnerability in Artifex Ghostscript before version 9.24.
What is the severity of CVE-2018-16541?
The severity of CVE-2018-16541 is high with a severity value of 5.5.
What is affected by CVE-2018-16541?
CVE-2018-16541 affects Artifex Ghostscript versions before 9.24.
How can I fix CVE-2018-16541?
To fix CVE-2018-16541, update Artifex Ghostscript to version 9.24 or higher.
Where can I find more information about CVE-2018-16541?
More information about CVE-2018-16541 can be found at the following references: [Reference 1](http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=241d91112771a6104de10b3948c3f350d6690c1d), [Reference 2](https://bugs.ghostscript.com/show_bug.cgi?id=699664), [Reference 3](https://www.artifex.com/news/ghostscript-security-resolved/)